Internal Audits Under ISM and ISPS: Who Needs One, How Often, and What a Good One Looks Like
Every ISM-certified company already knows an internal audit is a compliance requirement. Fewer treat it as what it actually is: the one mechanism built into the Code specifically to catch the gap between what your Safety Management System says happens and what actually happens on board. Get that gap wrong, and it usually surfaces at the worst possible moment: a Port State Control inspection, an accident, or something that started out as a near miss nobody thought was worth mentioning.
What the ISM Code actually requires
Every company operating under the ISM Code carries out internal safety audits, on board and ashore, at intervals not exceeding twelve months, to verify that safety and pollution-prevention activities comply with the SMS, a timeframe set out in Section 12.1. That interval can only be extended, and only by up to three months, in exceptional circumstances documented at the time, not justified afterward. Staying ahead of that date, rather than treating it as a deadline to catch up with, is most of what keeps this straightforward.
Section 12.4 adds the requirement that makes internal audits worth having: personnel carrying them out must be independent of the area being audited, unless that's genuinely impracticable given the size and nature of the company. An engineer cannot be the sole auditor of his own maintenance records. A captain cannot be the only auditor of bridge procedures he wrote himself. An external auditor satisfies that requirement cleanly regardless of team size: a genuine bonus for a small operation without a large shore-side team to draw an independent auditor from, and just as useful for a larger fleet that would rather keep its own compliance team focused on running the operation than auditing itself.
What the ISPS Code requires, and where it differs
The ISPS Code carries the same principle but not quite the same wording: personnel conducting internal audits of security activities must be independent of the activities audited, mirroring ISM almost exactly, under Part A/9.4.1. Arranging those audits is also a named duty of the Company Security Officer, under Part A/11.2.5.
Where it differs: ISM hardcodes a twelve-month maximum interval directly into the Code text. ISPS doesn't. Instead, the Ship Security Plan itself must specify the frequency of internal security audits, set by the company and approved by the flag state or Recognised Security Organisation. Most operators align it to twelve months to match their ISM cycle and run one audit programme rather than two, but that's a practical choice, not something the ISPS Code text mandates on its own.
Who actually needs one
In practice, the same threshold that pulls a vessel into ISM and ISPS in the first place pulls it into this requirement too: operating commercially, trading internationally, and crossing 500GT, the line an entire generation of yachts is deliberately designed to sit just under, at 499GT. Cross it, and internal audits under both codes are not optional extras. They're a certification requirement checked at DOC and SMC renewal, and increasingly checked by PSC directly during a routine inspection, not just at renewal time.
Vessels below that threshold, mini-ISM operations, and private yachts with no statutory SMS obligation at all aren't required to run a formal internal audit programme. The same logic that applies to having a DPA or CSO voluntarily applies here: the absence of a legal requirement doesn't remove the value of knowing whether your own procedures are actually being followed. A voluntary internal audit, or a gap analysis ahead of a move toward full certification, catches exactly the same problems a mandatory one does.
For vessels that are certified, Port State Control in this region checks internal audit compliance directly rather than taking the certificate's word for it: the date of the last audit, evidence the interval was met, and whether previous non-conformities were genuinely closed out rather than marked closed on paper.
What a good internal audit actually looks like
The most common pattern across SMS audits generally is a system that's well-written but not well-lived: procedures exist on paper, but the records tell a different story, or don't exist at all. A rigorous internal audit is built to close that gap, and it does it through evidence. A good auditor plans against defined criteria before stepping on board, works from drill logs, maintenance records, non-conformity reports, hours of rest records, and safety committee minutes, and asks the crew to run through a procedure in practice rather than simply describe it, giving them the chance to show the good work already being done, not just take their word for it.
Findings get categorised properly. A Major Non-Conformity threatens personnel, the ship, or the environment and demands immediate corrective action, potentially affecting DOC or SMC standing if left unresolved. A Minor Non-Conformity, sometimes recorded as a deficiency, doesn't carry that immediate threat but still needs corrective action closed out within an agreed timeframe, typically three months. An SMS audit that comes back with zero non-conformity reports year after year is not usually a sign of a well-run ship. It's usually a sign the reporting culture never took hold, and Port State Control officers in this region know that distinction well enough to treat an empty NCR log as a finding in itself.
Results have to reach the people who can act on them. Section 12.5 of the ISM Code requires audit results and reviews to be brought to the attention of all personnel with responsibility in the area concerned, and 12.6 requires management to take timely corrective action. An audit that produces a report nobody reads, or findings nobody actions before the next audit rolls around, has satisfied the paperwork requirement and missed the entire point of the exercise.
What an incident or near miss requires, separate from the audit cycle
Internal audits sit on a fixed schedule, but the Code doesn't wait for that schedule when something actually happens. Section 9.1 requires the SMS to include procedures for reporting, investigating, and analysing non-conformities, accidents, and hazardous occurrences, and IMO guidance is specific that a near miss counts as a hazardous occurrence in its own right, reportable and worth investigating regardless of the fact that nothing was damaged this time. Section 9.2 requires corrective action to follow, not just a written record of what happened.
This is usually where the gap between paper and practice opens up first, well before it reaches an audit. A tender that drops slightly during launch because of a worn davit fitting, or swings further than it should, is the kind of thing a crew can reasonably fix and get on with the day. Nothing broke, nobody was hurt, and reporting it can feel like making a fuss over nothing. That's exactly the hazardous occurrence Section 9 exists to capture: the version of the story that hasn't caused an accident yet. The same worn fitting causing an actual accident later is a considerably more expensive way to find out it needed attention.
None of this depends on the audit cycle, and a genuine near-miss reporting culture, one where reporting something small doesn't reflect badly on the crew, produces exactly the evidence a good internal audit later checks for. A safety record with no near-miss reports on file usually signals a reporting culture that hasn't taken hold, not a spotless one.
Case in point
The Costa Concordia disaster on 13 January 2012, in which the vessel struck rocks off Isola del Giglio after an unauthorised course deviation and 32 people died, is a widely studied example of exactly this gap. The official Italian investigation attributed the casualty to the Master's actions, but it also found a failed safety management culture in which the bridge team did not challenge decisions that departed from the ship's own procedures. That's not a claim that a missed internal audit caused the disaster. It's a documented instance of the precise failure mode a rigorous, evidence-based internal audit exists to surface before it reaches that point: a safety management system that looked complete on paper and was not being followed in practice. In the aftermath, Costa's parent company commissioned an audit of its own safety management system and the cruise industry adopted mandatory pre-departure muster drills across the board, exactly the kind of correction an internal audit is meant to force well before an incident makes it mandatory.
What a gap analysis actually is
The term gets used loosely, so it's worth being precise. A gap analysis compares current practice against a code's requirements before a formal certification audit rather than as part of one. It's the right tool for an operator preparing for first-time ISM or ISPS certification who wants to find the gaps before the Recognised Organisation's auditor does, and for a voluntary or mini-ISM operator who wants an honest picture of where they stand without entering formal certification at all. Less formal than a certified internal audit, considerably more useful than reading the Code cover to cover and guessing.
Who counts as independent, and who doesn't, really
Section 12.4's independence requirement gets satisfied on paper more often than it's satisfied in practice, and it's worth being honest about where the gap sits. The weakest version, common on smaller vessels, is one crew member auditing a different department: the engineer reviewing deck procedures, or vice versa. It technically meets the letter of the requirement, different area, different person, but that auditor reports to the same captain, works alongside the crew they're auditing every day, and has every social and professional reason not to write up something that reflects badly on a colleague they'll be at sea with next week. A shore-based company employee, a DPA or compliance manager auditing the vessel from ashore, is a step better, since they're removed from the daily crew dynamic, but they're still employed by the company whose interests are served by a clean report, and they may have written the procedures being audited in the first place. Where we already hold the DPA or CSO role for a vessel, that vessel's internal audits are carried out through a separate, independent associate arrangement rather than reviewing our own work, keeping the audit function genuinely separate from the role it's checking.
A genuinely external contractor removes both problems at once. No ongoing employment relationship with the company and no reputation to protect with the crew means a finding gets reported on its own merits, and paired with a practical way to fix it, rather than softened around who might be affected by raising it. Crew and company staff are almost always simply following the instructions and procedures they were given; a genuinely independent auditor's value is in spotting where those procedures could still go wrong and offering a workable fix, not in assigning blame for a system they didn't design. That's the version of independence Section 12.4 is actually describing, not the version that technically satisfies it. It's also where an external auditor adds value beyond the compliance requirement itself: a fresh set of eyes with no investment in the existing procedures tends to catch what a familiar one has stopped seeing, and cross-vessel experience means patterns that look normal on one boat, because that's simply how it's always been done there, get flagged for what they are elsewhere.
Who can conduct yours
We hold ISM/ISPS/MLC Internal Auditor certification through Lloyd's Maritime Institute, backed by two decades of worldwide command on commercially operated superyachts as an MCA Master 3000T. That combination matters more than the certificate alone: an auditor who has actually held the authority a captain exercises reads a bridge procedure, a drill log, or a maintenance record differently than one who has only studied the Code from ashore.
It also solves the independence problem directly, whether or not a compliance team already exists in-house. A large fleet with a dedicated compliance department still benefits from an external auditor providing genuine independence rather than reviewing its own work, and we're glad to work alongside that existing structure rather than in place of it; for a smaller operator, where the same handful of people write the procedures, run the ship, and would otherwise have to audit themselves, an external auditor closes the gap entirely. Being based across the South Pacific, New Zealand, Australian, and PNG time zones means audits, gap analyses, and pre-inspection reviews happen without delay, on a schedule built around the vessel's own operations.
What a contracted audit engagement looks like
A properly structured internal audit engagement is a formal arrangement, not a one-off visit. It sets out which vessels and which SMS or SSP are being audited, whether the scope covers ISM, ISPS, MLC, or all three, and the evidence trail expected: drill logs, maintenance records, NCR history, and whether prior corrective actions were actually closed out rather than just marked closed. It also covers how findings are categorised, the timeframe for corrective action, and, where a gap analysis or pre-inspection review is the actual goal, a plain-language readiness assessment rather than a formal audit report.
This isn't about replacing your existing management company's compliance function. Where one exists, we work alongside it, providing the independent audit function the Code requires. For an operator without an existing shore-side compliance structure, we can also run the full programme independently.
Resolving what an audit finds, not just reporting it
A finding that sits open until the next scheduled visit is exactly the pattern this whole article has been arguing against: a system that looks fine on paper because nobody has closed the gap yet. Wherever practical, corrective work coming out of an audit or gap analysis gets handled the same way the finding was raised, by desktop where the work is document or procedure based, and in person where it isn't. Being based in the South Pacific means attending a vessel in the region is a realistic option, not a multi-day transit from the other side of the world, so a finding raised in New Zealand, Australia, or the wider Pacific can actually get closed out while the vessel is still there, rather than logged as an action item for whenever an auditor is next passing through.
Summary
If your vessel is ISM or ISPS certified, the internal audit requirement is real, the independence requirement is real, and a genuinely evidence-based audit is the difference between a system that looks good on paper and one that actually holds up when Port State Control, or an incident, tests it. If your vessel sits below the certification threshold, the same audit, or a gap analysis ahead of one, is still one of the more straightforward pieces of risk management available, and considerably cheaper than finding the gap during a real inspection.
Contact us if you'd like to know more about how we can help with internal audits, gap analysis, or pre-inspection readiness, alongside your existing management structure or as your independent auditor.
Frequently asked questions
How often is an ISM internal audit required?
At intervals not exceeding twelve months, under Section 12.1 of the ISM Code. That interval can only be extended by up to three months, and only in exceptional, documented circumstances.
Does the ISPS Code require internal audits every twelve months too?
Not exactly. The ISPS Code requires the Ship Security Plan itself to specify the internal audit frequency, rather than fixing a number in the Code text. Most operators align it to twelve months to match their ISM cycle, but that's a practical choice rather than a hard requirement.
Can our own staff carry out internal audits?
Only if they're genuinely independent of the area being audited, which both Codes require unless it's impracticable due to the size and nature of the company. For smaller operators, that's usually where an external auditor becomes the more practical route to genuine independence, not just a compliance formality.
What's the difference between a Major and Minor non-conformity?
A Major Non-Conformity poses a serious threat to personnel, the ship, or the environment and requires immediate corrective action, potentially affecting DOC or SMC standing. A Minor Non-Conformity doesn't carry that immediate threat but still requires corrective action within an agreed timeframe, typically three months.
Do we need an internal audit if our vessel isn't ISM or ISPS certified?
Not legally, but the value of catching a gap between documented procedure and actual practice doesn't depend on certification status. A voluntary internal audit or gap analysis is one of the more straightforward pieces of risk management available to a mini-ISM operation or private vessel.
What's the difference between a gap analysis and an internal audit?
A gap analysis compares current practice against a code's requirements before formal certification, to find issues before a Recognised Organisation's auditor does. Internal audits are the ongoing requirement carried out once a vessel already holds ISM or ISPS certification, but it's worth seeing it for what it actually is beyond the paperwork: an essential, ongoing part of keeping the vessel genuinely safe and secure, not just a box checked at renewal.
Does an accident or near miss require an internal audit?
Not in those exact terms. Section 9 of the ISM Code requires any non-conformity, accident, or hazardous occurrence, including a near miss, to be reported, investigated, and followed by corrective action regardless of where the vessel sits in its twelve-month audit cycle. A significant incident is also normal grounds for a focused review of the area involved at the time, even though the Code doesn't formally call that follow-up review an internal audit in the Section 12 sense.
Have a question about this topic?
Book a free 15-minute call with Craig Hopkins — practical answers, no jargon.